CVE-2025-11187Patch(openssl / openssl)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch openssl openssl systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations. When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference. Exploiting this issue requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For this reason the issue was assessed as Moderate severity. The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as PKCS#12 processing is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue. OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do not support PBMAC1 in PKCS#12.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 3 mentions (2026-01-27); latest day: 2
  • 13 total mentions across 5 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline13 mentions / 5d
01223Mentions · 2026-01-27: 3Mentions · 2026-01-28: 3Mentions · 2026-01-29: 3Mentions · 2026-01-30: 2Mentions · 2026-02-02: 2PoC Mentioned / Linked · 2026-01-30: 1Patch / Workaround · 2026-01-27: 2Patch / Workaround · 2026-01-28: 2Patch / Workaround · 2026-01-29: 3Patch / Workaround · 2026-01-30: 2Patch / Workaround · 2026-02-02: 2Technical Details · 2026-01-28: 3Technical Details · 2026-01-29: 1Technical Details · 2026-01-30: 2Technical Details · 2026-02-02: 101-2701-2801-2901-3002-02
Signal classification2 categories
Patch
1076.9%
Disclosure
323.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-01-273
Disclosure1Patch2
2026-01-283
Disclosure1Patch2
2026-01-293
Patch3
2026-01-302
Disclosure1Patch1
2026-02-022
Patch2
Full discourse13 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    OpenSSL Security Advisory 27th January 2026 https://www.openwall.com/lists/oss-security/2026/01/27/7 12 CVEs, 2 stack-based buffer overflows CVE-2025-15467 Stack buffer overflow in CMS AuthEnvelopedData parsing (High) CVE-2025-11187 Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (Moderate)

    Post summary

    OpenSSL advisory from Jan 27, 2026 announces 12 CVEs, including two stack buffer overflows, but provides no PoC, exploit, or patch details, merely technical classifications and severity ratings.

    0401441.9K
    4.4K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl モジュール更新情報 3.5.5-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 openssl 3.5.5-1 この更新には脆弱性(CVE-2025-11187, CVE-2025-15469)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # dnf upgrade アップデート後、以下のコマ... https://kusanagi.tokyo/releases/22845/

    Post summary

    Kusanagi's OpenSSL module update to 3.5.5‑1 includes fixes for CVE‑2025‑11187 and CVE‑2025‑15469, which can be applied with "dnf upgrade" and the release link.

    01020164
    196 followersView on X
  • Kazuki Omo@omokazuki
    Patch

    OpenSSLの脆弱性(High: CVE-2025-15467, Moderate: CVE-2025-11187, Low: CVE-2025-15468等, CVE-2026-22795, 22796)と新バージョン(3.6.1, 3.5.5, 3.4.4, 3.3.6, 3.0.19) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssl #openssl https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260128/

    Post summary

    The post announces several OpenSSL CVEs and lists new patched versions, focusing on the availability of fixes rather than exploits or active attacks.

    00021425
    360 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    OpenSSL、危険度の高い複数の脆弱性など複数修正(CVE-2025-11187) https://rocket-boys.co.jp/security-measures-lab/openssl-fixes-multiple-high-severity-vulnerabilities-cve-2025-11187/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The article announces that OpenSSL CVE‑2025‑11187 and other high‑severity vulnerabilities have been patched. No exploit or active‑exploitation details are provided.

    10000168
    318 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    OpenSSL、危険度の高い複数の脆弱性など複数修正(CVE-2025-11187) https://rocket-boys.co.jp/security-measures-lab/openssl-fixes-multiple-high-severity-vulnerabilities-cve-2025-11187/

    Post summary

    The article announces that OpenSSL has released patches for multiple high‑severity vulnerabilities, including CVE-2025-11187, and directs readers to further details via the provided link.

    00000115
    45 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 OpenSSL Patches 12 Flaws, Including High-Severity Parsing Bugs That Could Enable RCE OpenSSL released updates fixing 12 vulnerabilities, including two high-severity stack buffer overflows (CVE-2025-15467 in CMS/PKCS#7 AEAD parsing and CVE-2025-11187 in PKCS#12 PBMAC1 processing) that can cause DoS and may be exploitable for remote code execution in certain scenarios. Most remaining issues are low-severity parsing/robustness bugs (NULL deref, OOB write/type confusion) and should be patched quickly where OpenSSL processes untrusted inputs. 🎯 Target: Global/Cryptography (OpenSSL users) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/openssl-patches-12-vulnerabilities-including-high-severity-rce-flaw

    Post summary

    OpenSSL has issued patches for 12 CVEs, including two high‑severity buffer overflows that could allow remote code execution; users are urged to apply the updates promptly.

    00000164
    196 followersView on X
  • Ostorlab@OstorlabSec
    Disclosure

    🚨 CVE-2025-11187 : OPENSSL PKCS#12 PBMAC1 STACK BUFFER OVERFLOW ALERT 🚨 @openssl_  A vulnerability has been disclosed in OpenSSL’s PKCS#12 verification — where parsing a crafted PKCS#12 (.p12/.pfx) using PBMAC1 can lead to a stack-based buffer overflow / crash, and in some conditions may be exploitable for code execution (platform- and hardening-dependent). Risk Severity: Moderate (OpenSSL rating); public PoC exists; risk increases materially for services that process untrusted PKCS#12 uploads/imports. Impact: • Denial of Service (crash) in applications that parse attacker-supplied PKCS#12 files[ citation:3] • Potential code execution in worst-case scenarios depending on mitigations (stack canaries/ASLR/NX and app context) • Credential-handling pipeline disruption (certificate management, VPN user bundle imports, S/MIME tooling) • Secondary failure modes reported include invalid/NULL pointer dereference paths (reliable crash primitives) Root Cause: CWE-120 (Buffer Copy without Checking Size of Input) / CWE-130 (Improper Handling of Length Parameter Inconsistency) When verifying a PKCS#12 file that uses PBMAC1 for the MAC, OpenSSL uses PBKDF2 parameters from the file (salt and keylength) without sufficient validation, which can drive unsafe writes into fixed-size stack buffers in the verification routine. Attackers can: • Deliver a malicious .p12/.pfx to any workflow that imports/validates PKCS#12 from external sources (uploads, email gateways, certificate portals, VPN enrollment) • Ensure the PKCS#12 uses PBMAC1 so the vulnerable verification path is exercised[ citation:3] • Trigger a stack overflow via attacker-controlled PBKDF2 keylength / malformed salt fields, crashing the process and potentially enabling exploitation in favorable conditions[ citation:3] • Repeatedly crash certificate-processing services for sustained DoS (and attempt exploitation where feasible) Are You Affected? Vulnerable: • OpenSSL 3.4.0, 3.5.0, 3.6.0 (per advisory/tracker guidance; depends on PBMAC1 usage path in PKCS#12 verification). • Highest risk where PKCS#12 is processed from untrusted sources (uploads/imports/automated ingestion). Fixed in: • OpenSSL 3.4.1, 3.5.1, and 3.6.1+ (branch fixes released in the January 2026 advisory window). Note: Many environments assume PKCS#12 files are “trusted admin input.” If your product accepts PKCS#12 from users/partners/customers, treat this as a materially higher risk than the “Moderate” label implies. Immediate Action Required: Update/Patch: • Upgrade to OpenSSL 3.4.1 / 3.5.1 / 3.6.1+ (choose the fixed release for your current branch) or apply your OS/vendor backport. Mitigation (if patching is delayed): • Restrict/disable PKCS#12 import/upload features where feasible; gate imports behind admin-only workflows. • Add strict validation controls: file size limits, content-type enforcement, and isolate PKCS#12 parsing into a sandboxed/helper process (blast-radius reduction). Audit & Monitor: • Monitor for crashes/SEGV in certificate-handling components and OpenSSL error patterns tied to pkcs12 verification. • Identify all services that parse .p12/.pfx (web portals, VPN tooling, PKI automation, email/S/MIME workflows). Incident Response: • If you suspect exploitation attempts: isolate affected services, preserve crash dumps/logs, and review PKCS#12 ingestion sources. If compromise is suspected, rotate impacted secrets/keys and rebuild from known-good baselines. If you process untrusted PKCS#12 anywhere, prioritize patching—this is a memory safety bug with public PoC, and the most realistic near-term outcome is reliable DoS, with RCE risk dependent on environment hardening. 🛡️

    Post summary

    The advisory discloses CVE-2025-11187, a stack buffer overflow in OpenSSL’s PKCS#12 PBMAC1 verification, provides a public PoC, detailed technical info, and patch and mitigation guidance.

    00000147
    581 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 OpenSSL Patches 12 Flaws Including High-Severity Pre-Auth RCE Risks in CMS/PKCS#12 Parsing OpenSSL released fixes for 12 vulnerabilities, with the most serious being CVE-2025-15467 (stack overflow in CMS AuthEnvelopedData AEAD IV parsing, affecting OpenSSL 3.0–3.6) and CVE-2025-11187 (PBMAC1 parameter validation leading to stack overflow during PKCS#12 MAC verification, affecting 3.4–3.6), both potentially enabling DoS and under certain conditions remote code execution when parsing untrusted inputs. 🎯 Target: Global/Software Supply Chain (OpenSSL Consumers) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/187445/security/openssl-issued-security-updates-to-fix-12-flaws-including-remote-code-execution.html

    Post summary

    OpenSSL has issued patches for 12 vulnerabilities, including two high‑severity CVEs (CVE‑2025‑15467 and CVE‑2025‑11187) that could allow remote code execution via CMS/PKCS#12 parsing, and the article announces these fixes.

    00000129
    196 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl Module Update 3.5.5-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: openssl 3.5.5-1 This update includes support for vulnerability(CVE-2025-11187, CVE-2025-15469). The module update can be applied... https://kusanagi.tokyo/en/releases/22846/

    Post summary

    KUSANAGI released an OpenSSL module update (3.5.5-1) that patches CVE-2025-11187 and CVE-2025-15469, providing a fix for the affected component.

    0000086
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 OpenSSL Patches 12 Bugs Including High-Severity RCE-Grade Overflows in CMS/PKCS#12 Parsing OpenSSL’s Jan 27, 2026 security release fixes 12 vulnerabilities, including a High-severity stack overflow in CMS AuthEnvelopedData parsing (CVE-2025-15467) and a Moderate PKCS#12 PBMAC1 parameter-validation bug (CVE-2025-11187) that can crash apps and may enable code execution depending on mitigations. Upgrade to patched releases (e.g., 3.6.1 / 3.5.5 / 3.4.4, plus 3.3.6 and 3.0.19 where applicable) and treat any workflow that parses untrusted CMS/PKCS#7 or PKCS#12 files as internet-facing attack surface. 🎯 Target: Global/Software & Supply Chain #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.infosecurity-magazine.com/news/12-openssl-flaws/

    Post summary

    The article announces OpenSSL’s 12‑bug fix release, highlighting a high‑severity stack overflow in CMS parsing and a moderate PKCS#12 crash bug, and urges users to upgrade their OpenSSL versions to mitigate potential remote code execution.

    00000148
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 OpenSSL patches critical CMS stack overflow (CVE-2025-15467) that can lead to pre-auth code execution OpenSSL’s latest advisory fixes multiple flaws, led by CVE-2025-15467 where a crafted CMS AuthEnvelopedData message with an oversized AES-GCM IV can overflow a stack buffer before authentication, enabling crashes and potential RCE in apps that parse untrusted CMS/PKCS#7. Upgrade to 3.6.1 / 3.5.5 / 3.4.4 / 3.3.6 / 3.0.19 (and review PKCS#12/PBMAC1 handling via CVE-2025-11187) to reduce exposure. 🎯 Target: Global/Cryptographic Infrastructure (servers, S/MIME/CMS consumers) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cyberpress.org/openssl-vulnerabilities-remote-execute-malicious-code/

    Post summary

    OpenSSL has fixed a critical CMS stack overflow (CVE‑2025‑15467) that could lead to pre‑auth code execution; users should upgrade to the listed versions as no active exploitation or PoC is reported.

    00000157
    196 followersView on X
  • 〒@teenigma_
    Disclosure

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    An OpenSSL security advisory enumerating multiple CVEs with associated severity levels and a reference link.

    00000156
    348 followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.1 Is Now Available with Important Security Patches and Bug Fixes This release addresses CVE-2025-11187, CVE-2025-15467, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, and CVE-2025-69419. https://9to5linux.com/openssl-3-6-1-is-now-available-with-important-security-patches-and-bug-fixes

    Post summary

    The article announces the OpenSSL 3.6.1 release, highlighting that it contains patches for several CVEs.

    00000158
    130 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more